GIAC Security Essentials (GSEC) 2025 Practice Exam Questions and Answers – Part 14/15

Practice for the GIAC Security Essentials (GSEC) exam with 14 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: What is an effective defense against port scanning?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the GSEC practice test →

What you will practice

  • What is an effective defense against port scanning?
  • A private company has recently landed a government contract to provide support services for military personne…
  • What is the MOST important aspect of a disaster recovery plan to ensure the potential for a successful recove…
  • How would you assess the biggest threats to the mission-critical processes of an organization while crafting…
  • Why are advanced persistent threats (APT) considered a highly serious, even panic-inducing security violation?
  • When should law enforcement be contacted when an incident being handled by the intrusion response team is lik…

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. What is an effective defense against port scanning?

Answer: C. C) Minimize the number of open ports.

Minimizing open ports effectively defends against port scanning by reducing the attack surface. Host intrusion detection systems only alert on scanning activity, and multi-factor authentication prevents unauthorized access.

Q2. A private company has recently landed a government contract to provide support services for military personnel. To comply with the contract requirements, the company needs to alter the mechanism used to manage access control over resources…

Answer: D. D) MAC

Mandatory access control is required because it enforces clearance labels and need-to-know compartmentalization typically seen in military environments. Discretionary access control is ruled out because it relies on data owners rather than strict system rules.

Q3. What is the MOST important aspect of a disaster recovery plan to ensure the potential for a successful recovery?

Answer: A. A) Offsite storage of backups

Offsite storage of backups is the most critical element because data cannot be recovered if all local copies are destroyed. Warm sites and clusters are useful for availability, but they are useless for data restoration without actual backups.

Q4. How would you assess the biggest threats to the mission-critical processes of an organization while crafting a business continuity plan?

Answer: A. A) By performing a business impact analysis

A business impact analysis evaluates the consequences of disruptions to mission-critical processes during planning. Vulnerability scans and penetration tests are technical assessments, whereas continuity planning focuses on business risk and operational survival.

Q5. Why are advanced persistent threats (APT) considered a highly serious, even panic-inducing security violation?

Answer: A. A) They grant ongoing undiscovered continued remote access to an IT infrastructure.

Advanced persistent threats grant attackers ongoing undiscovered remote access, allowing them to quietly mine data over long periods. Despite the name, they do not always cause immediate downtime and are not necessarily the most sophisticated attacks.

Q6. When should law enforcement be contacted when an incident being handled by the intrusion response team is likely to be a computer crime?

Answer: B. B) Immediately upon discovery

Law enforcement must be contacted immediately upon discovering a likely crime to ensure proper forensic collection of court-admissible evidence. Waiting until after containment or eradication risks contaminating the scene and destroying evidence.

Q7. Why is a business continuity plan an essential element of a company security strategy?

Answer: B. B) To maintain availability

A business continuity plan is essential because it maintains the availability of mission-critical processes during a disruptive event. It focuses on keeping the business running rather than directly protecting confidentiality or reducing operational costs.

Q8. What is the first step an adversary would perform when seeking to break into a system?

Answer: A. A) Reconnaissance

Reconnaissance is always the first step of an attack, allowing adversaries to gather preliminary information about the target. Enumeration happens later alongside scanning, while clearing tracks and pilfering data occur after a breach is successful.

Q9. Which aspect of AAA services is implemented to ensure that the proper individual is held accountable for their actions, and requires multiple elements?

Answer: B. B) Authentication

Authentication proves identity, and multi-factor authentication makes impersonation much harder. Accounting tracks and logs actions, but strong authentication is the specific mechanism that requires multiple elements and reliably ensures the correct individual is held accountable.

Q10. A threat evaluation process is performed during the design of a business continuity plan or disaster recovery plan that evaluates risk in light of work process, and resembles the technique used when designing security policies. What is thi…

Answer: A. A) Business impact analysis

A business impact analysis evaluates risks by focusing on how threats affect critical business tasks rather than individual assets. Threat modeling is closely related, but business impact analysis specifically guides business continuity and disaster recovery planning.

Q11. Why is disabling the SSID broadcast NOT an effective means of hiding a wireless network from attackers? (Choose two.)

Answer: A,D. A) Radio waves can still be detected. || D) Other management frames contain the SSID.

Disabling the SSID broadcast fails because radio waves remain physically detectable and probe responses leak the SSID. Hiding the network name only inconveniences users, as attackers can easily extract it from other wireless management frames.

Q12. How can an incident response team's handling of a violating event be improved before any damaging activity occurs?

Answer: C. C) Expanded preparedness, including attack analysis, vulnerability research, and response drills

Expanded preparedness through training, vulnerability research, and drills directly improves incident response before an event happens. Post-mortem reviews are valuable, but they occur after an incident, making preparation the correct proactive step.

Q13. How do security policies serve as insurance against being found negligent in a court case?

Answer: A. A) They may satisfy due care and due diligence.

Security policies demonstrate that an organization meets legal standards for due care and due diligence. They do not guarantee breach prevention, and simply spending money or logging events does not legally prove proper security practices were followed.

Q14. The incident response team has three main goals or purposes. Which of the following is NOT one of those goals?

Answer: D. D) Educate users.

An incident response team focuses on preventing, detecting, and responding to violations, not educating users. Security awareness training is a critical security management responsibility, but it falls outside the core incident handling lifecycle.

More GSEC drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top